Issued on 11/21/2024 | Posted on 11/25/2024 | Report number: A-18-21-08014 To cut to the chase: What OIG Found OCR fulfilled its requirement under the HITECH Act to perform periodic HIPAA audits. However: OCR’s HIPAA audit implementation was too narrowly scoped to effectively assess ePHI protections and demonstrate a reduction of risks within the health care sector. Specifically: OCR’s audits consisted…
UK: All outpatient appointments cancelled as Arrowe Park Hospital hit with ‘cyber attack’
Emma Dukes reports: Wirral University Teaching Hospital Trust said the incident began on Monday evening (November 25), with staff members at the hospital telling LiverpoolWorld that a “cyber attack” had caused the computer systems to go down. The Trust – which comprises Arrowe Park Hospital, Clatterbridge Hospitals and the Wirral Women and Children’s Hospital – confirmed that a “major…
Ca: LifeLab loses its last attempt to withhold data breach forensics report from public eyes
It’s been a long battle, but transparency has prevailed. LifeLabs LP v. Information and Privacy Commissioner of Ontario (IPC) stemmed from a cyberattack in 2019 that resulted in the compromise of 15 million Canadian’s data. LifeLab eventually complied with inquiries by the Privacy Commissioner, who requested that LifeLab provide its forensics report and other documents, but LifeLab…
Attorney General James and DFS Superintendent Harris Secure $11.3 Million from Auto Insurance Companies over Data Breaches
NEW YORK – New York Attorney General Letitia James and New York State Department of Financial Services (DFS) Superintendent Adrienne A. Harris today secured $11.3 million in penalties from two auto insurance companies, the Government Employees Insurance Company (GEICO) and The Travelers Indemnity Company (Travelers), for having poor data security which led to the personal information…
Irish researcher finds 1.1 million NHS employee records were leaked
James Cox reports: A Dublin cybersecurity researcher, Aaron Costello, has found that 1.1 million NHS employee records were leaked online because of improper configuration settings in Microsoft Power Pages, a software platform used by over 250 million people a month to build websites. Mr Costello, who works with AppOmni, previously discovered a computer glitch meant the HSE’s…
Pacific Pulmonary Medical Group patient information dumped by Everest Ransomware Team
The Pacific Pulmonary Medical Group (PPMG) in California has a significant data breach problem, but if you were to visit its website today, you’d have no clue that anything is amiss. On October 25, Everest Team added PPMG to its dark web leak site. The unencrypted personal and protected health information that they subsequently dumped…